Description
iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
Remediation
References
https://github.com/itext/itext7/pull/78
https://github.com/itext/itext7/pull/78#issuecomment-1089282165
https://github.com/itext/itext7/releases/tag/7.1.18
Related Vulnerabilities
CVE-2021-21294 Vulnerability in maven package org.http4s:http4s-blaze-server_2.13
CVE-2017-5651 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2022-31127 Vulnerability in npm package next-auth
CVE-2016-10586 Vulnerability in npm package macaca-chromedriver
CVE-2019-11818 Vulnerability in maven package org.opencms:org.opencms.workplace.tools.accounts